DEBIAN-CVE-2015-3885

Advisory lineage Upstream: 1 Downstream: 3
Published: 19 May 2015, 18:59
Last modified:08 Jan 2026, 16:17

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 May 2015, 18:59
Published
Vulnerability first disclosed
08 Jan 2026, 16:17
Last Modified
Vulnerability information updated

Description

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.

Affected Systems

  • debiandarktable

    < 1.6.7-1 | < 1.6.7-1 | < 1.6.7-1 | < 1.6.7-1

  • debiandcraw

    < 9.26-1 | < 9.26-1 | < 9.26-1 | < 9.26-1

  • debianexactimage

    < 0.9.1-5 | < 0.9.1-5 | < 0.9.1-5 | < 0.9.1-5

  • debianfreeimage

    < 3.15.4-6 | < 3.15.4-6 | < 3.15.4-6 | < 3.15.4-6

  • debiankodi

    < 16.0+dfsg1-1 | < 16.0+dfsg1-1 | < 16.0+dfsg1-1

  • debianlibraw

    < 0.16.2-1 | < 0.16.2-1 | < 0.16.2-1 | < 0.16.2-1

  • debianrawtherapee

    < 4.2-2 | < 4.2-2 | < 4.2-2 | < 4.2-2

References (1)